feat(store): each object store sets how long its transfer grants last, 12 hours by default - #32
Open
earakely-scale wants to merge 3 commits into
Conversation
…, 12 hours by default The built-in object stores (S3, GCS and the local store) take a grant_lifetime_seconds setting, 12 hours unless configured, and their read and write grants last that long when the caller names no lifetime. agent-env no longer names one (it asked for a fixed hour), so a grant lasts what the store that issues it says, and a local run's grants follow the store that owns each object. A lifetime a store cannot sign is refused when the store is made: S3 caps SigV4 at 7 days, and GCS at 12 hours when it signs through IAM or 7 days with a key. The changelog upload policy still lasts the agent's TTL, which it must cover. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
earakely-scale
requested review from
a team and
polakamtejas
as code owners
September 30, 2026 22:25
… a lifetime must outlast a transfer LocalRunObjectStore now passes expires_in on only when its caller named one, so a store whose grant methods default it to a number of their own keeps that default instead of receiving None. A store's grant_lifetime_seconds must be at least 15 minutes, longer than the 10 minutes agent-env waits for an agent to move an object through a grant, and the local store's at most 7 days, as S3's, so a value it could not turn into an expiry is refused when the store is made rather than at its first grant. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ansfer-grants' into edgararakelyan/store-grant-lifetime
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Each object store now sets how long its transfer grants last, instead of agent-env asking for a fixed hour. The default is 12 hours. Stacked on #13.
A setting on every built-in store.
S3ObjectStore,GcsObjectStoreandLocalFilesystemObjectStoretakegrant_lifetime_secondsin their config table (default43200), and it applies to read and write grants. A caller can still passexpires_in.ObjectStore.grant_lifetime_secondscarries the default for other stores.agent-env no longer picks the lifetime.
write_object,read_objectand the validator's probe callissue_write_grant/issue_read_grantwithoutexpires_in, whose default is nowNone, meaning the store's setting.GRANT_LIFETIME_SECONDSis gone.@localrouting, each grant is issued, and timed, by the store that owns its object.expires_inis passed on only when the caller named one, so a custom store's own default is left alone.expires_indefault still behaves exactly as before.Checked when the store is made. The value must be a whole number of seconds and at least 15 minutes (
MIN_GRANT_LIFETIME_SECONDS), which outlasts the 10 minutes agent-env waits for a transfer. It can be no more than the store can sign: 7 days for S3's SigV4, for GCS 12 hours when signing through IAM or 7 days with a key, and 7 days for the local store. 12 hours is exactly the GCS IAM maximum, so the default is valid on every store.expires_atsays so.Unchanged: the changelog upload policy. It keeps lasting the agent's TTL, which it must cover for the whole capture.
Longer grants mean a leaked grant URL stays valid longer. Deployments that want the old window can set
grant_lifetime_seconds = 3600.Test plan
pytest tst/unit packages/agentenv-protocol/tests -n auto: 5775 passed.expires_instill honoured.@localrouting leaves a custom store's ownexpires_indefault alone.@localrouting following the owning store; and the setting read from[stores.object]config.pytest -m 'not int_test_slow' tst/integration --ignore=tst/integration/env/gateway/gateway_test.py: 141 passed.🤖 Generated with Claude Code
The PR appears safe to merge; none of the previous findings remains outstanding.
Summary
Object stores now set the default lifetime for read and write grants, with a configurable 12-hour default. Agent-env leaves the lifetime unset so the store that owns an object can choose its expiry.
@localrouting, each grant uses the default of the store that owns its object.Diagram
%%{init: {'theme': 'neutral'}}%% flowchart LR A[Agent transfer] --> B[Issue grant without a lifetime] B --> C{Local routing?} C -- Yes --> D[Store that owns the object] C -- No --> E[Configured store] D --> F[Store chooses grant lifetime] E --> FReviews (3) · Last reviewed commit: "Merge remote-tracking branch 'origin/edg..."